Vulnerabilities (CVE)

Filtered by vendor Sillytavern
Filtered by product Sillytavern
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26286 1 Sillytavern 1 Sillytavern 2026-02-20 N/A 8.5 HIGH
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.16.0, a Server-Side Request Forgery (SSRF) vulnerability in the asset download endpoint allows authenticated users to make arbitrary HTTP requests from the server and read the full response body, enabling access to internal services, cloud metadata, and private network resources. The vulnerabi ...

Show More